Having troubles logging in here with this account, keeps making me put my password with every page and I am selecting remember me....
This is user account: "manny"
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:31:40 AM, 1/19/2006
+ Report-Checksum: 1A39040
+ Scan result:
HKLM\SOFTWARE\Toolbar -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Downloads -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Files -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Install -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\PlugIns -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Server -> Spyware.WebSearch : Error during cleaning
::Report End
Webroot Spysweeper LOG
********
11:35 AM: | Start of Session, Thursday, January 19, 2006 |
11:35 AM: Spy Sweeper started
11:35 AM: Sweep initiated using definitions version 602
11:35 AM: Starting Memory Sweep
11:38 AM: Memory Sweep Complete, Elapsed Time: 00:03:20
11:38 AM: Starting Registry Sweep
11:38 AM: Found Adware: websearch toolbar
11:38 AM: HKLM\software\toolbar\ (6 subtraces) (ID = 646240)
11:39 AM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 146513)
11:39 AM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 646239)
11:39 AM: Registry Sweep Complete, Elapsed Time:00:01:05
11:39 AM: Starting Cookie Sweep
11:39 AM: Found Spy Cookie: pointroll cookie
11:39 AM: hehehe@ads.pointroll[1].txt (ID = 3148)
11:39 AM: Found Spy Cookie: advertising cookie
11:39 AM: hehehe@advertising[1].txt (ID = 2175)
11:39 AM: Found Spy Cookie: ask cookie
11:39 AM: hehehe@ask[1].txt (ID = 2245)
11:39 AM: Found Spy Cookie: atlas dmt cookie
11:39 AM: hehehe@atdmt[2].txt (ID = 2253)
11:39 AM: Found Spy Cookie: centrport net cookie
11:39 AM: hehehe@centrport[1].txt (ID = 2374)
11:39 AM: Found Spy Cookie: questionmarket cookie
11:39 AM: hehehe@questionmarket[1].txt (ID = 3217)
11:39 AM: Found Spy Cookie: tribalfusion cookie
11:39 AM: hehehe@tribalfusion[1].txt (ID = 3589)
11:39 AM: zakariya@ads.pointroll[2].txt (ID = 3148)
11:39 AM: zakariya@atdmt[1].txt (ID = 2253)
11:39 AM: zakariya@centrport[1].txt (ID = 2374)
11:39 AM: zakariya@tribalfusion[2].txt (ID = 3589)
11:39 AM: Cookie Sweep Complete, Elapsed Time: 00:00:08
11:39 AM: Starting File Sweep
12:12 PM: File Sweep Complete, Elapsed Time: 00:33:09
12:13 PM: Full Sweep has completed. Elapsed time 00:37:54
12:13 PM: Traces Found: 24
12:17 PM: Removal process initiated
12:17 PM: Quarantining All Traces: websearch toolbar
12:17 PM: websearch toolbar is in use. It will be removed on reboot.
12:17 PM: HKLM: software\toolbar\ is in use. It will be removed on reboot.
12:17 PM: Quarantining All Traces: advertising cookie
12:17 PM: Quarantining All Traces: ask cookie
12:17 PM: Quarantining All Traces: atlas dmt cookie
12:17 PM: Quarantining All Traces: centrport net cookie
12:17 PM: Quarantining All Traces: pointroll cookie
12:17 PM: Quarantining All Traces: questionmarket cookie
12:17 PM: Quarantining All Traces: tribalfusion cookie
12:17 PM: Removal process completed. Elapsed time 00:00:19
********
12:49 PM: | Start of Session, Tuesday, January 17, 2006 |
12:49 PM: Spy Sweeper started
12:49 PM: Sweep initiated using definitions version 602
12:49 PM: Starting Memory Sweep
12:52 PM: Memory Sweep Complete, Elapsed Time: 00:02:58
12:52 PM: Starting Registry Sweep
12:53 PM: Found Adware: websearch toolbar
12:53 PM: HKLM\software\toolbar\ (6 subtraces) (ID = 646240)
12:53 PM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 146513)
12:53 PM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 646239)
12:53 PM: Registry Sweep Complete, Elapsed Time:00:01:04
12:53 PM: Starting Cookie Sweep
12:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:07
12:54 PM: Starting File Sweep
1:30 PM: File Sweep Complete, Elapsed Time: 00:36:18
1:30 PM: Full Sweep has completed. Elapsed time 00:40:36
1:30 PM: Traces Found: 13
1:33 PM: Removal process initiated
1:34 PM: Quarantining All Traces: websearch toolbar
1:34 PM: websearch toolbar is in use. It will be removed on reboot.
1:34 PM: HKLM: software\toolbar\ is in use. It will be removed on reboot.
1:34 PM: Removal process completed. Elapsed time 00:00:21
1:47 PM: IE Security Shield: found: C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE -- IE Security modification allowed at user request
11:34 AM: Warning: Failed to register registry notification for "HKLM\Software\Microsoft\Windows\CurrentVersion\Run": Access is denied
11:35 AM: | End of Session, Thursday, January 19, 2006 |
********
12:47 PM: | Start of Session, Tuesday, January 17, 2006 |
12:47 PM: Spy Sweeper started
12:48 PM: Warning: Failed to register registry notification for "HKLM\Software\Microsoft\Windows\CurrentVersion\Run": Access is denied
12:49 PM: | End of Session, Tuesday, January 17, 2006 |
****************************************
Logfile of HijackThis v1.99.1
Scan saved at 12:20:01 PM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.activision.com/spider-man
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) -
http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
YES that last post was about rocky account, and thank you very much for all the toiling...